Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Advisory/Mitigation Campaign

Operation CameraSwarm exploitation of Dahua authentication-bypass flaws

Updated 19.08.2026 21:09
Case score 78
Members 3 First seen 19.08.2026 14:34 Latest activity 19.08.2026 21:09

Overview

Attackers used **CVE-2021-33044** and **CVE-2021-33045** in **Operation CameraSwarm** to compromise more than **14,530 Dahua devices** between June 17 and July 22, 2026, combining the authentication-bypass flaws with credential attacks and a P2P relay path. Hunt.io said the operation left **1,923 cameras** configured with a persistent account and reached **283 cameras** through the P2P route, with confirmed compromises concentrated in **Ukraine** and **Russia**. **CISA** still lists both Dahua flaws in the **Known Exploited Vulnerabilities** catalog and directs operators to apply vendor mitigations or discontinue use if mitigations are unavailable. **Dahua** says fixed firmware is available, so the current picture is confirmed exploitation followed by ongoing patch-and-remove pressure for exposed camera fleets.
Latest development Open development history 1 earlier development Hunt.io discloses Operation CameraSwarm against Dahua devices Hunt.io says Operation CameraSwarm compromised more than 14,530 Dahua devices between June 17 and July 22, 2026 by combining credential attacks, CVE-2021-33044, CVE-2021-33045, and a P2P relay path; the researchers say 1,923 cameras were configured with a persistent account, 283 were reached through P2P, and confirmed compromises were concentrated in Ukraine and Russia. Users of affected Dahua products are advised to install the corresponding fix software or newer firmware, and ITRES Labs recommends disabling P2P where it is not required and checking firmware against the vendor's download site.
  1. Earlier development

    CISA keeps Dahua authentication-bypass flaws in the KEV catalog

    CISA kept CVE-2021-33044 and CVE-2021-33045 listed in the Known Exploited Vulnerabilities catalog for Dahua IP camera authentication-bypass vulnerabilities and directed operators of affected Dahua cameras and related products to apply vendor mitigations or discontinue use if mitigations are unavailable.

Signals

Impact signals
Exploitation
CVEs/products
Geographic context
Remediation
Status

Tooling context

3 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability Dahua cameras authentication-bypass vulnerabilities (multiple vulnerabilities)
Updated 19.08.2026 14:34 Lead Contribution 78
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**CVE-2021-33044** and **CVE-2021-33045** are **authentication-bypass** flaws in **Dahua cameras and related products** that let attackers bypass device identity checks during login. Hunt.io linked the flaws to **Operation CameraSwarm**, which compromised **more than 14,530 Dahua IP cameras** between **June 17 and July 22, 2026** using **TCP/37777 brute-forcing**, **cloud-relay access**, and exploitation of the CVEs to install a persistent **p2pwn** backdoor account on **1,923 cameras**. The researchers also said **283 cameras** were reached through **P2P** and recovered **407 MB** of operator data. **Dahua** lists **fixed firmware**, and **CISA KEV** still tracks both issues as exploited vulnerabilities.

Advisory/Mitigation CISA KEV guidance for Dahua IP camera authentication-bypass flaws (CVE-2021-33044, CVE-2021-33045)
Updated 19.08.2026 14:34 Context
Exploitation Active Exploitation CVSS 9.8 Critical Urgency Immediate Patch Patch Available

**CISA** kept **CVE-2021-33044** and **CVE-2021-33045** in the **KEV catalog** for **Dahua IP camera authentication-bypass vulnerabilities**, directing defenders to **apply vendor mitigations** or **discontinue use** if mitigations are unavailable. The guidance covers affected **Dahua cameras and related products** as of **August 19, 2026**, leaving exposed systems on notice for urgent remediation.

Campaign Operation CameraSwarm campaign targeting Dahua devices
Updated 19.08.2026 14:34 Context
Campaign Active Patch Patch Available

**Hunt.io** disclosed **Operation CameraSwarm**, a **35-day** campaign that compromised **more than 14,530 Dahua IP cameras** mostly in **Ukraine and Russia**. The operation used **TCP/37777 brute-forcing**, **CVE-2021-33044**, **CVE-2021-33045**, and a **cloud-relay** path that relied on serial numbers and SDK credentials to reach **283 cameras** behind NAT. Hunt.io also reported **1,923 cameras** were configured with a persistent **p2pwn** account, recovered **407 MB** of operator data, and said some toolkit references to **CVE-2024-39943** and **CVE-2025-31702** were misleading and not part of the observed attacks. Owners of affected **Dahua** devices were advised to check for **p2pwn**, disable **P2P** when not needed, and apply **Dahua SA-2021-0130** firmware updates or later versions.